GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

The supply chain campaign known as GlassWorm has once again reared its head, infiltrating both Microsoft Visual Studio Marketplace and Open VSX with 24 extensions impersonating popular developer tools and frameworks like Flutter, React, Tailwind, Vim, … Continue reading GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools→

Posted in Uncategorized

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

Cybersecurity researchers have disclosed details of an npm package that attempts to influence artificial intelligence (AI)-driven security scanners.
The package in question is eslint-plugin-unicorn-ts-2, which masquerades as a TypeScript extension of t… Continue reading Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools→

Posted in Uncategorized

Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks

Israeli entities spanning academia, engineering, local government, manufacturing, technology, transportation, and utilities sectors have emerged as the target of a new set of attacks undertaken by Iranian nation-state actors that have delivered a previ… Continue reading Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks→

Posted in Uncategorized

SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities

Vulnerability management is a core component of every cybersecurity strategy. However, businesses often use thousands of software without realising it (when was the last time you checked?), and keeping track of all the vulnerability alerts, notificatio… Continue reading SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities→

Posted in Uncategorized

Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild

Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild.
The patch addresses a total of 107 security flaws spanning different components, including … Continue reading Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild→

Posted in Uncategorized

India Orders Phone Makers to Pre-Install Sanchar Saathi App to Tackle Telecom Fraud

India’s telecommunications ministry has reportedly asked major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days.
According to a report from Reuters, the app cannot be del… Continue reading India Orders Phone Makers to Pre-Install Sanchar Saathi App to Tackle Telecom Fraud→

Posted in Uncategorized

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware

A threat actor known as ShadyPanda has been linked to a seven-year-long browser extension campaign that has amassed over 4.3 million installations over time.
Five of these extensions started off as legitimate programs before malicious changes were intr… Continue reading ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware→

Posted in Uncategorized

⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More

Hackers aren’t kicking down the door anymore. They just use the same tools we use every day — code packages, cloud accounts, email, chat, phones, and “trusted” partners — and turn them against us.
One bad download can leak your keys. One weak vendor ca… Continue reading ⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More→

Posted in Uncategorized

Webinar: The “Agentic” Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams

The AI browser wars are coming to a desktop near you, and you need to start worrying about their security challenges.
For the last two decades, whether you used Chrome, Edge, or Firefox, the fundamental paradigm remained the same: a passive window thro… Continue reading Webinar: The “Agentic” Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams→

Posted in Uncategorized

New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control

A new Android malware named Albiriox has been advertised under a malware-as-a-service (MaaS) model to offer a “full spectrum” of features to facilitate on-device fraud (ODF), screen manipulation, and real-time interaction with infected devices.
The mal… Continue reading New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control→

Posted in Uncategorized